Section III HIPCAR – Cybercrime/e-Crimes (6) Computer Data The drafters decided to base the definition of computer data on international standards. In order to ensure that all types of content are covered the drafters provided examples in brackets. (7) Computer Data Storage Medium Not only the capacity but also the size and function of computer storage devices have changed within the last decades. The drafters decided to formulate an open definition that covers mass storage devices as well as micro storage systems that are for example used in car keys. This provision is therefore applicable to both permanent as well as short-term storage devices (such as RAM). (8) Critical Infrastructure Today computer systems are not only used by private persons and businesses but also by the operators of critical infrastructure, such as energy supply or traffic control. As infrastructure that is considered critical varies from country to country the drafters decided to include a broad definition of critical infrastructure. (9) Devices The drafters decided to provide an open ended approach to the application of provisions referring to a device by providing a set of examples. This list of examples is therefore not conclusive or limited but open for new developments. (10) Hinder Some of the international approaches to address Cybercrime criminalize the illegal hindering of computer systems without providing a precise definition of what is covered by the Act. The drafters decided to ensure that the term hindering includes network based attacks (such as the transmission of computer data) as well as physical attacks. Accidental cuts of power supply are covered by definition but are excluded from criminal liability as the related provision (Sec. 9) requires the commission of the act as well as intent. (11) Hosting Provider Similar to the definition of other categories of Internet service providers, the term hosting provider not only includes a legal person but also a natural person. It is not necessary that the hosting provider possesses storage devices. The operator of a website that allows users to post messages also acts as a hosting provider. (12) Hyperlink The drafters decide to regulate the criminal responsibility of a hyperlink provider. In this context the law provides a broad definition of hyperlink to cover the various different technical solutions. (13) Interception The interception of data transfer processes is a procedural instrument that can be found in different international approaches to address Cybercrime. However, most of these instruments do not specify the acts or provide details of the legitimate investigation procedures. The drafters decided to include some examples for both legitimate acts as well as the types of communication that can be interception. (14) Multiple Electronic Mail Messages The drafters recognised the potential negative impact of SPAM for developing countries. One essential component of a criminalisation of SPAM is the definition of multiple messages. In light of this the drafters decided to require at least one thousand (1,000) messages. > Model Policy Guidelines & Legislative Text 31

Select target paragraph3